StackRadar

CVE-2024-47554

High

Advisory

Published 3 Oct 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
355
of 17,781 indexed, latest versions
Container images
389
deployed by those charts
Fix available
1 of 1
affected package

Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader

Carried by container images the latest versions of 355 of 17,781 indexed charts deploy, on 389 images.

Affected packageAffected versionsFixed inImages
commons-iomaven2.0, 2.1, 2.2, 2.3+10 more2.14.0389
OSV records
GHSA-78wr-2p64-hpwj

Charts affected

355 by stars
ChartLatestAffected imagesRadar Score
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
commons-io@2.8.0
2.14.0

Open the chart page →

7,713
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
commons-io@2.7
2.14.0

Open the chart page →

1,413
akto-ai-guardrails-v2akto0.3.01 of 6See more

akto-ai-guardrails-v2 akto 0.3.0

1 of the 6 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
commons-io@2.6
2.14.0

Open the chart page →

9,321
akto-testing-db-layerakto1.42.161 of 2See more

akto-testing-db-layer akto 1.42.16

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
commons-io@2.6
2.14.0

Open the chart page →

5,489
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
commons-io@2.6
2.14.0

Open the chart page →

3,442
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
commons-io@2.11.0
2.14.0
hazelcast/management-center:5.3.2f9d34300d330
commons-io@2.7
2.14.0

Open the chart page →

28,131
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
commons-io@2.2
2.14.0

Open the chart page →

11,553
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
commons-io@2.5
2.14.0

Open the chart page →

5,277
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.02 of 4See more

james-kompose appscode 0.1.0

2 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
commons-io@2.7
2.14.0
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
commons-io@2.8.0
2.14.0

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
commons-io@2.4
2.14.0

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
commons-io@2.6
2.14.0

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
commons-io@2.8.0
2.14.0

Open the chart page →

13,352
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
commons-io@2.6
2.14.0

Open the chart page →

7,936
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
commons-io@2.11.0
2.14.0

Open the chart page →

4,145
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
commons-io@2.11.0
2.14.0

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
commons-io@2.3
2.14.0

Open the chart page →

5,806
blackduck-alertblackduck8.4.01 of 4See more

blackduck-alert blackduck 8.4.0

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
blackducksoftware/blackduck-alert:8.4.090cca32de2cc
commons-io@2.8.0
2.14.0

Open the chart page →

4,292
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
commons-io@2.8.0
2.14.0

Open the chart page →

1,816
geoservercamptocamp20.0.35 of 12See more

geoserver camptocamp2 0.0.3

5 of the 12 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
commons-io@2.10.0
2.14.0
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
commons-io@2.10.0
2.14.0

Open the chart page →

88,335
opensearch-singlenodecaptnbpVerified publisher1.0.91 of 2See more

opensearch-singlenode captnbp 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0

Open the chart page →

1,073
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
commons-io@2.6
2.14.0

Open the chart page →

6,447
gocdcloudnativeapp1.9.22 of 2See more

gocd cloudnativeapp 1.9.2

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gocd/gocd-agent-alpine-3.9:v19.3.053588bd3221f
commons-io@2.6
2.14.0
gocd/gocd-server:v19.3.02da45cb09d57
commons-io@2.6
2.14.0

Open the chart page →

9,144
metabasecloudnativeapp0.5.01 of 1See more

metabase cloudnativeapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
metabase/metabase:v0.31.2ffb2dccacefc
commons-io@2.5
2.14.0

Open the chart page →

4,601
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
commons-io@2.6
2.14.0

Open the chart page →

2,837
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
commons-io@2.4
2.14.0

Open the chart page →

7,226
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
commons-io@2.4
2.14.0

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
commons-io@2.6
2.14.0

Open the chart page →

22,442
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
commons-io@2.11.0
2.14.0

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
commons-io@2.5
2.14.0
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
commons-io@2.5
2.14.0

Open the chart page →

16,860
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
commons-io@2.11.0
2.14.0

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.12 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

2 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
commons-io@2.5
2.14.0
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
commons-io@2.5
2.14.0

Open the chart page →

58,857
ldapd4nVerified publisher0.1.01 of 1See more

ldap d4n 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dwimberger/ldap-ad-it:latest0c636e55eb82
commons-io@2.4
2.14.0

Open the chart page →

1,657
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
commons-io@2.5
2.14.0

Open the chart page →

8,245
deployhubdeployhubVerified publisher10.0.4151 of 11See more

deployhub deployhub 10.0.415

1 of the 11 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/deployhub/ms-ui:svccat-v11.0.815-g717581f5dedbc31e6f
commons-io@2.8.0
2.14.0

Open the chart page →

11,160
spark-standalonedmwm-bigdataVerified publisher0.1.01 of 2See more

spark-standalone dmwm-bigdata 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
gradiant/spark:2.4.4-python-alpine97657d56e927
commons-io@2.4
2.14.0

Open the chart page →

6,147
api-postsdniel0.9.11 of 1See more

api-posts dniel 0.9.1

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/api-posts:master45a667852f2a
commons-io@2.6
2.14.0

Open the chart page →

8,986
forwardauthdniel2.0.131 of 1See more

forwardauth dniel 2.0.13

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
dniel/forwardauth:latestf67129ea1c64
commons-io@2.6
2.14.0

Open the chart page →

4,592
drogue-cloud-coredrogue-iotVerified publisher0.7.111 of 22See more

drogue-cloud-core drogue-iot 0.7.11

1 of the 22 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

55,666
drogue-cloud-twindrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-twin drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0054ef67eb7da
commons-io@2.7
2.14.0

Open the chart page →

6,915
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
library/neo4j:3.3.0d4eaa8484246
commons-io@2.4
2.14.0

Open the chart page →

11,174
spark-shuffleduyet0.2.01 of 1See more

spark-shuffle duyet 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0

Open the chart page →

5,639
rundeckdwardu-helm-charts0.3.41 of 2See more

rundeck dwardu-helm-charts 0.3.4

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0

Open the chart page →

19,802
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
commons-io@2.6
2.14.0

Open the chart page →

2,237
entrypoint-balancereclipse-aeriosVerified publisher1.3.01 of 1See more

entrypoint-balancer eclipse-aerios 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
commons-io@2.11.0
2.14.0

Open the chart page →

2,512
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-47554.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
commons-io@2.6
2.14.0

Open the chart page →

11,482

Container images carrying it

389 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
opensearchproject/opensearch:2.15.01963b3ece46d
commons-io@2.8.0
2.14.0
1
opensearchproject/opensearch:2.14.0466a49f379bb
commons-io@2.7
2.14.0
1
opensearchproject/opensearch:2.12.0645d3d9390ad
commons-io@2.8.0
2.14.0
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
commons-io@2.7
2.14.0
1
openwhisk/invoker:1.0.0f5831ec85525
commons-io@2.6
2.14.0
1
owasp/dependency-track:3.8.0efc65e702ee1
commons-io@2.6
2.14.0
1
pcarrascoponce/planner:v1.0981fc482442c
commons-io@2.6
2.14.0
1
pedrocesarti/jmeter-docker:3.314851f144f57
commons-io@2.5
2.14.0
1
penpotapp/exporter:2.2.15c835ffd87ab
commons-io@2.5
2.14.0
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
commons-io@2.8.0
2.14.0
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
commons-io@2.5
2.14.0
1
radarbase/radar-redcapintegration:1.0.6fcd973d4796d
commons-io@2.5
2.14.0
1
raykrueger/riemann:0.2.14c8baf3de57bb
commons-io@2.5
2.14.0
1
refar/apm-api:v5.7.1241373fa2972
commons-io@2.2
2.14.0
1
remche/shinyproxy:2.6.18bcda8a04d3b
commons-io@2.7
2.14.0
1
reportportal/service-api:5.7.29df41f8fb320
commons-io@2.6
2.14.0
1
reportportal/service-authorization:5.7.09e73114dbd15
commons-io@2.6
2.14.0
1
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
commons-io@2.11.0
2.14.0
1
rm3l/dev-feed-api:latest9a7f732245a3
commons-io@2.11.0
2.14.0
1
rodolpheche/wiremock:2.27.22328a9fce2bf
commons-io@2.2
2.14.0
1
rundeck/rundeck:3.2.74d64fe56f767
commons-io@2.2
2.14.0
1
rundeck/rundeck:3.0.16b13e8059ad72
commons-io@2.2
2.14.0
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
commons-io@2.7
2.14.0
1
seataio/seata-server:latest703b5de7f1a6
commons-io@2.7
2.14.0
1
seataio/seata-server:1.5.1ee1ed55f4144
commons-io@2.7
2.14.0
1
sismics/docs:v1.10f4b0ef019cf1
commons-io@2.6
2.14.0
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
commons-io@2.4
2.14.0
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
commons-io@2.6
2.14.0
1
snappydatainc/spark-shuffle:v2.2.0-kubernetes-0.5.1fd4b2070466f
commons-io@2.4
2.14.0
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
commons-io@2.8.0
2.14.0
1
sonatype/nexus3:3.58.1586060431b64
commons-io@2.11.0
2.14.0
1
sslhep/hive-metastore:3.1.39e80af083079
commons-io@2.5
2.14.0
1
sslhep/servicex-did-finder:v1.8.5ab0090083567
commons-io@2.8.0
2.14.0
1
sslhep/x509-secrets:v1.8.5d9e9ecb12d59
commons-io@2.8.0
2.14.0
1
structurizr/onpremises:2025.11.094b5ffb5119c8
commons-io@2.8.0
2.14.0
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
commons-io@2.6
2.14.0
1
thehiveproject/cortex:3.1.7f4bc64fb8844
commons-io@2.5
2.14.0
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
commons-io@2.11.0
2.14.0
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
commons-io@2.11.0
2.14.0
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
commons-io@2.11.0
2.14.0
1
thingsboard/tb-node:3.4.1645f43b688f7
commons-io@2.11.0
2.14.0
1
thingsboard/tb-node:3.6.0f40a542832c4
commons-io@2.11.0
2.14.0
1
thmmniii/fbs-core:v1.27.15438517d9fc2
commons-io@2.11.0
2.14.0
1
thmmniii/fbs-runner:v1.27.186105349c1a3
commons-io@2.13.0
2.14.0
1
tock/bot_api:25.10.7dd5d5c70e333
commons-io@2.4
2.14.0
1
tock/kotlin_compiler:25.10.7c9c0fb40089a
commons-io@2.4
2.14.0
1
traccar/traccar:6.7-alpine621c8d6d46fd
commons-io@2.11.0
2.14.0
1
treskon/portrait:DEV-latest88e813f22347
commons-io@2.11.0
2.14.0
1
trinodb/trino:45038c6f24ab1a4
commons-io@2.11.0
2.14.0
1
trinodb/trino:405ee80ab5eeab2
commons-io@2.11.0
2.14.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.